Trust & Privacy

How we handle your information

This page is maintained by Crown & Compass Travel to answer common security and privacy questions about our booking and inquiry experience. It is editable project content and is not an independent certification or third-party audit.

What we collect

When you send an inquiry, we collect the name, email address, and trip details you provide so we can respond and plan your journey. Account holders (the travel host and collaborators) also have an authenticated profile used to manage trip listings and the daily destination spotlight.

We do not request or store passport numbers, payment card numbers, or financial account details on this site. Bookings are completed off-platform through the travel agent using a separate, secure credit card authorization process.

How information is protected

Inquiry submissions and trip content are stored in our managed backend with row-level security enabled on every customer-data table. Write access to trip listings and the destination spotlight is restricted to authenticated admin accounts; public visitors can only read the published content shown on this site.

Administrative database functions are scoped to the backend service role only and are not callable by signed-in users or the public. Connections between your browser and our backend use TLS in transit.

Authentication

Sign-in is available to the travel host and authorized collaborators. We use email and password authentication backed by our managed auth provider. Visitors do not need to create an account to browse trips, view the spotlight, or send an inquiry.

Images and storage

Trip and destination spotlight images are served from private storage buckets through time-limited URLs. Uploads and edits to those images are restricted to admins via row-level security policies.

Subprocessors and integrations

We rely on a small set of trusted infrastructure providers to operate the site:

  • Hosting, database, authentication, and storage: Lovable Cloud
  • Daily destination spotlight content and imagery: Lovable AI Gateway
  • Transactional and authentication email delivery: Lovable Emails

We do not sell your information, and we do not share inquiry data with advertising networks.

Cookies and analytics

The site uses only the cookies and local storage required to keep an admin signed in and to remember session state. We do not run third-party advertising trackers on this site.

Data retention and deletion

Inquiry messages are retained for as long as needed to respond and plan your trip. If you would like your inquiry, contact details, or any other personal information we hold deleted, contact us at the address below and we will remove it from our systems.

Security contact

If you believe you have found a security issue, please reach out through the inquiry form on the homepage and mark your message as a security report. We will acknowledge and investigate promptly.

Shared responsibility

Crown & Compass Travel maintains the application, content, and customer-facing controls described here. Underlying platform capabilities — including managed database security, authentication, storage, and email infrastructure — are operated by Lovable Cloud. Travelers are responsible for protecting access to their own email inbox used to receive itineraries and confirmations.